vendor:
Privileged User Manager
by:
rgod, juan vazquez
N/A
CVSS
N/A
Remote Code Execution
N/A
CWE
Product Name: Privileged User Manager
Affected Version From: NetIQ Privileged User Manager 2.3.1
Affected Version To: NetIQ Privileged User Manager 2.3.1
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2003 SP2
2012
NetIQ Privileged User Manager 2.3.1 ldapagnt_eval() Remote Perl Code Execution
This module abuses a lack of authorization in the NetIQ Privileged User Manager service (unifid.exe) to execute arbitrary perl code. The problem exists in the ldapagnt module. The module has been tested successfully on NetIQ PUM 2.3.1 over Windows 2003 SP2, which allows to execute arbitrary code with SYSTEM privileges.
Mitigation:
N/A